EtwpReadPerSiloConfigParameters
NTSTATUS __fastcall EtwpReadPerSiloConfigParameters(INT64 a1, INT64 a2, WCHAR a3){
NTSTATUS v4;
void *v5;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
int v8;
unsigned int *v9;
_RTL_QUERY_REGISTRY_TABLE result[2];
unsigned int v11;
void *KeyHandle;
KeyHandle = 0i64;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
v11 = 64;
DestinationString = 0i64;
RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\WMI", a3);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes) < 0
|| (memset((INT64)result, 0i64),
result[0].QueryRoutine = (int(__fastcall *)(wchar_t *, unsigned int, void *, unsigned int, void *, void *))EtwpQueryRegistryCallback,
result[0].EntryContext = &v8,
result[0].Name = L"EtwMaxLoggers",
result[0].DefaultType = 4,
v8 = 4,
v9 = &v11,
(int)RtlQueryRegistryValuesEx(0x40000000ui64, (const WCHAR *)KeyHandle, result, 0i64, 0i64) < 0) )
{
v4 = v11;
}
else
{
v4 = 256;
if( v11 <= 0x100 )
{
v4 = v11;
if( v11 < 0x20 )
v4 = 32;
}
v11 = v4;
}
v5 = KeyHandle;
*(_DWORD *)(a1 + 16) = v4;
if( v5 )
return ZwClose(v5);
return v4;
}Referenced by:
EtwInitializeSiloState